← DINEO

Privacy Policy

Version 1.0.0 · Last updated 18 September 2026

Who we are

DINEO is a restaurant discovery and reservation platform operated by Lasla d.o.o., a company registered in Croatia, trading as DINEO. Lasla d.o.o. is the data controller for the personal data described here and decides how and why it is processed. Guests use DINEO to find venues, read menus and request tables. Restaurant owners use it to manage their venue, menu and reservations; for data an owner holds about their own guests, the venue acts as controller and we act as processor on their behalf. Questions about this policy, or any request about your data, can be sent to support@shadowos.com.co.

Data we collect

  • Account data: email address, name and phone number you enter yourself, plus your interface language.
  • Reservation data: the venue, date, time, party size, contact details and any note you add to a booking.
  • Activity data: favourites, recently viewed venues and reviews you write after a completed visit.
  • Owner data: venue details, menu content, opening hours, team members and verification details you submit.
  • Technical data: basic request and error logs needed to keep the service secure and working.

Device permissions

The mobile app requests only two permissions, and only when you use the related feature:

  • Camera — to scan a restaurant QR code and open its menu. Camera images are never stored or uploaded.
  • Notifications — to tell you when a venue confirms, declines or changes your reservation.

We do not request contacts, photos, microphone or background location. Sharing your location for distances is optional and handled by your browser or system prompt, and is never stored on our servers.

How we use your data

To create and secure your account, deliver reservation requests to the venue you chose, show your bookings and their status, keep your favourites and language preference, and provide venue owners with the information they need to accept a booking. We do not sell your personal data and do not use it for third-party advertising.

Legal basis for processing

  • Performance of a contract — creating and running your account, delivering reservation requests, showing bookings, providing a paid plan and its features.
  • Legal obligation — tax, accounting and invoicing records relating to paid plans, and responding to lawful requests.
  • Legitimate interests — keeping the service secure, preventing fraud and abuse, and improving how the product works, balanced against your rights.
  • Consent — optional features you switch on, such as notifications, camera QR scanning, sharing your location for distances, and any marketing messages. You can withdraw consent at any time.

Who can see your data

A reservation is shared only with the venue you booked, so its team can prepare your table and contact you. Each venue's data is fully separated from every other venue. Access rules are enforced in the database, not only in the app.

Who we share data with

  • Service providers — hosting, database, authentication and support tooling, acting on our instructions.
  • Stripe Payments Europe, Ltd. — our payment processor. Stripe handles checkout, card processing and subscription billing for paid plans. When you buy a plan, your billing details and payment data are collected and processed by Stripe under Stripe's privacy policy; we never see or store your full card details.
  • Professional advisers — legal and accounting advisers where necessary.
  • Authorities — where we are required to disclose data by law.

Where data is transferred outside the EEA, we rely on adequacy decisions or standard contractual clauses. All traffic is encrypted over HTTPS, and we apply access controls, encryption and database-level access rules as technical and organisational security measures.

Cookies

We use only essential cookies and local storage needed to keep you signed in and remember your language choice. We do not use advertising or cross-site tracking cookies. Checkout pages provided by Stripe may set their own cookies needed to process a payment. You can clear cookies and local storage at any time in your browser settings.

Retention and your rights

Account and reservation data is kept while your account exists and for as long as required for legal and accounting purposes. You can view and edit your details in your profile, and you can request access, correction, export or deletion of your data by writing to support@shadowos.com.co. Data no longer needed is deleted or anonymised; invoicing records are kept for the period required by tax law.

You have the right to access, rectification, erasure, restriction of processing, portability, objection, and withdrawal of consent, and you may complain to your data protection supervisory authority (in Croatia, AZOP). We answer requests within one month.

Children

DINEO is not intended for children under 16.

Changes

If this policy changes we will update the date above and, for significant changes, notify you in the app.